CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2021-39275: Apache HTTP Server Out-of-Bounds Write

July 20, 2026

CVE-2021-39275 is an out-of-bounds write vulnerability in Apache HTTP Server 2.4.48 and earlier, rated low risk by Apache. It was patched in version 2.4.49 in 2021 and is flagged by Censys as exploited in the wild, though not in CISA's KEV catalog.